Unknown · Sustainable Irrigation Platform · CVE-2026-58476
**Name of the Vulnerable Software and Affected Versions**
Sustainable Irrigation Platform (SIP) versions prior to 5.2.17
**Description**
Cross-site request forgery occurs when a logged-in administrator is lured to a malicious page that issues HTTP GET requests. The system fails to perform CSRF token validation or origin verification, allowing remote attackers to execute state-changing administrative actions. These actions include disabling the passphrase, rebooting the device, deleting programs, or installing plugins. In default configurations, these endpoints are exposed to unauthenticated users because no passphrase is required and the default credential is `opendoor`.
**Recommendations**
Update Sustainable Irrigation Platform (SIP) to version 5.2.17 or later.
Change the default credential `opendoor` and enable a strong passphrase to prevent unauthenticated access to administrative endpoints.